[ { "cveID": "CVE-2026-41679", "euvdID": "EUVD-2026-25166", "vendorProject": "paperclipai", "product": "@paperclipai/server, paperclip", "dateReported": "2026/08/17", "patchedSince": "2026/04/22", "originSource": "CNW", "shortDescription": "An unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in authenticated mode with default configuration.", "exploitationType": ["unknown"], "cwes": ["CWE-287","CWE-862","CWE-1188"], "notes": "https://github.com/paperclipai/paperclip/security/advisories/GHSA-68qg-g8mg-6pr7" }, { "cveID": "CVE-2026-73570", "euvdID": "EUVD-2026-58069", "vendorProject": "Zimbra", "product": "Collaboration", "dateReported": "2026/08/18", "patchedSince": "2026/07/20", "originSource": "CERT.PL", "shortDescription": "Improper sanitization of untrusted input during SNMP notification processing. Exploitation waves since the beginning of August 2026.", "exploitationType": ["unknown"], "cwes": ["CWE-78"], "notes": "https://wiki.zimbra.com/wiki/Zimbra_Releases/10.1.20" }, { "cveID": "CVE-2026-42897", "euvdID": "EUVD-2026-30343", "vendorProject": "Microsoft", "product": "Microsoft Exchange Server", "dateReported": "2026/08/18", "patchedSince": "2026/05/14", "originSource": "CERT.PL", "shortDescription": "Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.", "exploitationType": ["unknown"], "cwes": ["CWE-79"], "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897" }, { "cveID": "CVE-2026-12569", "euvdID": "EUVD-2026-37831", "vendorProject": "PTC", "product": "Windchill PDMLink, FlexPLM", "dateReported": "2026/08/16", "patchedSince": "2026/06/18", "originSource": "ENISA", "shortDescription": "Critical RCE vulnerability caused by insecure deserialization of untrusted data.", "exploitationType": ["ransomware"], "cwes": ["CWE-20","CWE-502"], "notes": "https://www.ptc.com/en/about/trust-center/advisory-center/active-advisories/windchill-flexplm-rce-vulnerability" }, { "cveID": "CVE-2026-59310", "euvdID": "EUVD-2026-51097", "vendorProject": "VMware", "product": "vCenter", "dateReported": "2026/08/10", "patchedSince": "2026/08/03", "originSource": "ENISA", "shortDescription": "Directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this issue to execute arbitrary code.", "exploitationType": ["APT"], "cwes": ["CWE-22"], "notes": "https://medium.com/@quirso_de/active-exploitation-of-cve-2026-59310-361-victim-ips-across-47-countries-9783187cc6ff" }, { "cveID": "CVE-2026-68820", "euvdID": "EUVD-2026-56468", "vendorProject": "Microsoft", "product": "Windows", "dateReported": "2026/08/11", "patchedSince": "2026/08/11", "originSource": "ENISA", "shortDescription": "Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.", "exploitationType": ["APT"], "cwes": ["CWE-416"], "notes": "https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/" }, { "cveID": "CVE-2017-10271", "euvdID": "EUVD-2017-1918", "vendorProject": "Oracle Corporation", "product": "WebLogic Server", "dateReported": "2026/08/10", "patchedSince": "2017/10/17", "originSource": "NCSC HU", "shortDescription": "Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Security).", "exploitationType": ["ransomware"], "cwes": ["CWE-306"], "notes": "https://github.com/c0mmand3rOpSec/CVE-2017-10271" }, { "cveID": "CVE-2022-26134", "euvdID": "EUVD-2022-30701", "vendorProject": "Atlassian", "product": "Confluence Server, Confluence Data Center", "dateReported": "2026/07/31", "patchedSince": "2022/06/02", "originSource": "CNW", "shortDescription": "OGNL injection vulnerability allows an unauthenticated attacker to execute arbitrary code on an instance.", "exploitationType": ["APT"], "threatActorsExploiting": ["UNC6586"], "cwes": ["CWE-917"], "notes": "https://socradar.io/blog/snowlight-government-chinese-campaign/" }, { "cveID": "CVE-2026-49049", "euvdID": "EUVD-2026-40122", "vendorProject": "JoomShaper", "product": "Helix3 extension for Joomla", "dateReported": "2026/07/10", "patchedSince": "2026/06/29", "originSource": "CNW", "shortDescription": "Helix3 plugin for Joomla exposes an ajax handler task that allows unauthenticated attackers to delete arbitrary files, write arbitrary JSON files and update template parameters.", "exploitationType": ["unknown"], "cwes": ["CWE-284"], "notes": "https://www.joomshaper.com/forum/question/45671" }, { "cveID": "CVE-2026-48907", "euvdID": "EUVD-2026-34789", "vendorProject": "Widget Factory (Pty) Ltd", "product": "Joomla Content Editor (JCE)", "dateReported": "2026/07/06", "patchedSince": "2026/06/03", "originSource": "CERT-PL", "shortDescription": "Critical vulnerability in JCE editor extension.", "exploitationType": ["unknown"], "cwes": ["CWE-284"], "notes": "https://www.joomlacontenteditor.net/news/jce-pro-2-9-99-5-released" }, { "cveID": "CVE-2026-48908", "euvdID": "EUVD-2026-38110", "vendorProject": "JoomShaper", "product": "SP Page Builder extension for Joomla", "dateReported": "2026/07/06", "patchedSince": "2026/06/20", "originSource": "CERT-PL", "shortDescription": "Critical vulnerability that allows unauthenticated users to upload arbitrary files.", "exploitationType": ["unknown"], "cwes": ["CWE-434"], "notes": "https://www.joomshaper.com/forum/question/45152" }, { "cveID": "CVE-2026-1731", "euvdID": "EUVD-2026-5559", "vendorProject": "BeyondTrust", "product": "Remote Support (RS), Privileged Remote Access (PRA)", "dateReported": "2026/06/04", "patchedSince": "2026/02/26", "originSource": "NCSC-FI", "shortDescription": "Critical pre-authentication RCE vulnerability.", "exploitationType": ["unknown"], "cwes": ["CWE-78"], "notes": "https://www.beyondtrust.com/trust-center/security-advisories/bt26-02" }, { "cveID": "CVE-2026-41940", "euvdID": "EUVD-2026-26246", "vendorProject": "WebPros", "product": "cPanel", "dateReported": "2026/05/08", "patchedSince": "2026/04/28", "originSource": "CERT-PL", "shortDescription": "cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.", "exploitationType": ["ransomware"], "cwes": ["CWE-306"], "notes": "https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026" }, { "cveID": "CVE-2024-42009", "euvdID": "EUVD-2024-39391", "vendorProject": "RoundCube", "product": "Webmail", "dateReported": "2026/04/27", "patchedSince": "2024/08/04", "originSource": "CERT-PL", "shortDescription": "A Cross-Site Scripting vulnerability in Roundcube through 1.5.7 and 1.6.x through 1.6.7 allows a remote attacker to steal and send emails of a victim via a crafted e-mail message that abuses a Desanitization issue in message_body() in program/actions/mail/show.php.", "exploitationType": ["APT"], "threatActorsExploiting": ["UNC1151"], "cwes": ["CWE-79"], "notes": "https://cert.pl/en/posts/2025/06/unc1151-campaign-roundcube/" }, { "cveID": "CVE-2025-55182", "euvdID": "EUVD-2025-2009839", "vendorProject": "Meta", "product": "React Server Components", "dateReported": "2026/04/08", "patchedSince": "2025/12/03", "originSource": "CNW", "shortDescription": "Flaw in how React decodes payloads sent to React Server Function endpoints enabled unauthenticated remote code execution. Apps supporting React Server Components may still be vulnerable even if not implementing any React Server Function endpoints.", "exploitationType": ["APT"], "notes": "https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components#update-instructions" }, { "cveID": "CVE-2025-53770", "euvdID": "EUVD-2025-23309", "vendorProject": "Microsoft", "product": "SharePoint", "dateReported": "2026/04/08", "patchedSince": "2025/07/19", "originSource": "CNW", "shortDescription": "Microsoft confirmation of active attacks targeting on-premises SharePoint Server customers by exploiting vulnerabilities partially addressed by the July Security Update.", "exploitationType": ["APT"], "cwes": ["CWE-502"], "notes": "https://www.microsoft.com/en-us/msrc/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770" }, { "cveID": "CVE-2025-4428", "euvdID": "EUVD-2025-14387", "vendorProject": "Ivanti", "product": "Endpoint Manager Mobile (EPMM)", "dateReported": "2026/04/08", "patchedSince": "2026/05/13", "originSource": "CNW", "shortDescription": "High severity vulnerability. Successful exploitation may lead to unauthenticated remote code execution when chained together with CVE-2025-4427.", "exploitationType": ["APT"], "cwes": ["CWE-94"], "notes": "https://ccb.belgium.be/advisories/warning-actively-exploited-zero-day-vulnerabilities-ivanti-endpoint-manager-mobile-epmm" }, { "cveID": "CVE-2025-4427", "euvdID": "EUVD-2025-14388", "vendorProject": "Ivanti", "product": "Endpoint Manager Mobile (EPMM)", "dateReported": "2026/04/08", "patchedSince": "2026/05/13", "originSource": "CNW", "shortDescription": "Medium severity vulnerability. Successful exploitation may lead to unauthenticated remote code execution when chained together with CVE-2025-4428.", "exploitationType": ["APT"], "cwes": ["CWE-288"], "notes": "https://ccb.belgium.be/advisories/warning-actively-exploited-zero-day-vulnerabilities-ivanti-endpoint-manager-mobile-epmm" }, { "cveID": "CVE-2025-22457", "euvdID": "EUVD-2025-9646", "vendorProject": "Ivanti", "product": "Ivanti Connect Secure", "dateReported": "2026/04/08", "patchedSince": "2025/02/11", "originSource": "CNW", "shortDescription": "Evidence of active exploitation in the wild against ICS 9.X (end of life) and 22.7R2.5 and earlier versions since April 2025.", "exploitationType": ["unknown"] }, { "cveID": "CVE-2026-20963", "euvdID": "EUVD-2026-2114", "vendorProject": "Microsoft", "product": "Microsoft SharePoint", "dateReported": "2026/03/12", "patchedSince": "2026/02/13", "originSource": "CNW", "shortDescription": "Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.", "exploitationType": ["unknown"], "cwes": ["CWE-502"], "notes": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20963" }, { "cveID": "CVE-2026-1281", "euvdID": "EUVD-2026-4940", "vendorProject": "Ivanti", "product": "Endpoint Manager Mobile (EPMM)", "dateReported": "2026/01/29", "patchedSince": "2026/05/07", "originSource": "CNW", "shortDescription": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.", "exploitationType": ["unknown"], "notes": "https://www.ncsc.nl/alert/casus-kwetsbaarheden-ivanti-epmm-systemen" }, { "cveID": "CVE-2026-1340", "euvdID": "EUVD-2026-4936", "vendorProject": "Ivanti", "product": "Endpoint Manager Mobile (EPMM)", "dateReported": "2026/01/29", "patchedSince": "2026/05/07", "originSource": "cnw", "shortDescription": "A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.", "exploitationType": ["unknown"], "notes": "https://www.ncsc.nl/alert/casus-kwetsbaarheden-ivanti-epmm-systemen" }, { "cveID": "CVE-2025-59719", "euvdID": "EUVD-2025-202191", "vendorProject": "Fortinet", "product": "Fortiweb", "dateReported": "2026/01/27", "patchedSince": "2025/12/09", "originSource": "CERT-AT", "shortDescription": "An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.", "exploitationType": ["unknown"], "notes": "https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-ldap-connection-passwords, https://www.cert.at/en/blog/2026/1/look-at-forticloud-sso-bypass-exploitation" }, { "cveID": "CVE-2025-59718", "euvdID": "EUVD-2025-202198", "vendorProject": "Fortinet", "product": "FortiOS,FortiProxy,FortiSwitchManager", "dateReported": "2026/01/27", "patchedSince": "2025/12/09", "originSource": "CERT-AT", "shortDescription": "A improper verification of cryptographic signature vulnerability in Fortinet FortiOS, FortiProxy, FortiSwitchManager allows an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML response message.", "exploitationType": ["unknown"], "notes": "https://www.cert.at/en/blog/2026/1/threat-actors-use-forticloud-to-collect-ldap-connection-passwords, https://www.cert.at/en/blog/2026/1/look-at-forticloud-sso-bypass-exploitation" }, { "cveID": "CVE-2025-25231", "euvdID": "EUVD-2025-24160", "vendorProject": "Omnissa", "product": "Omnissa Workspace ONE UEM", "dateReported": "2025/09/09", "patchedSince": "2025/08/11", "originSource": "CERT-PL", "shortDescription": "Omnissa Workspace ONE UEM contains a Secondary Context Path Traversal Vulnerability. A malicious actor may be able to gain access to sensitive information by sending crafted GET requests (read-only) to restricted API endpoints", "cwes": ["CWE-22"], "notes": "https://moje.cert.pl/komunikaty/2025/29/aktywnie-wykorzystywana-krytyczna-podatnosc-w-narzedziu-omnissa-workspace-one-uem-airwatch-mdm/", "exploitationType": ["unknown"] }, { "cveID": "CVE-2025-6543", "euvdID": "EUVD-2025-19085", "vendorProject": "Citrix", "product": "NetScaler ADC and NetScaler Gateway", "dateReported": "2025/07/18", "patchedSince": "2025/06/25", "originSource": "CNW", "shortDescription": "Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server", "exploitationType": ["unknown"] }, { "cveID": "CVE-2010-0738", "euvdID": "EUVD-2010-0764", "vendorProject": "Red Hat", "product": "JBoss Application Server", "dateReported": "2025/07/14", "patchedSince": "2010/10/12", "originSource": "CERT Italia", "shortDescription": "This management interface allows administrative operations to be performed without adequate access controls allowing a remote attacker to interact with the system in an unauthorized manner", "notes": "https://www.acn.gov.it/portale/w/distribuzione-di-payload-malevoli-tramite-vulnerabilita-note", "exploitationType": ["unknown"] }, { "cveID": "CVE-2011-4085", "euvdID": "EUVD-2011-4036", "vendorProject": "Red Hat", "product": "JBoss Application Server", "dateReported": "2025/07/14", "patchedSince": "2011/12/08", "originSource": "CERT Italia", "shortDescription": "Some management interfaces remain accessible and lack effective access control mechanisms", "notes": "https://www.acn.gov.it/portale/w/distribuzione-di-payload-malevoli-tramite-vulnerabilita-note", "exploitationType": ["unknown"] }, { "cveID": "CVE-2015-7501", "euvdID": "EUVD-2022-3799", "vendorProject": "Apache", "product": "Commons Collections library", "dateReported": "2025/07/14", "patchedSince": "2015/11/12", "originSource": "CERT Italia", "shortDescription": "the system accepts serialized objects without verifying their origin or reliability allowing an attacker to send specially crafted payloads that are then deserialized and executed", "exploitationType": ["unknown"], "notes": "https://www.acn.gov.it/portale/w/distribuzione-di-payload-malevoli-tramite-vulnerabilita-note" }, { "cveID": "CVE-2017-12149", "euvdID": "EUVD-2017-3733", "vendorProject": "Red Hat", "product": "JBoss Application Server", "dateReported": "2025/07/14", "patchedSince": "2018/05/17", "originSource": "CERT Italia", "shortDescription": "Servlet exposes an endpoint that allows you to invoke Java Management Extensions (JMX) operations without any authentication or access control", "exploitationType": ["unknown"], "notes": "https://www.acn.gov.it/portale/w/distribuzione-di-payload-malevoli-tramite-vulnerabilita-note" }, { "cveID": "CVE-2024-55591", "euvdID": "EUVD-2024-52819", "vendorProject": "Fortinet", "product": "FortiOS/FortiProxy", "dateReported": "2025/02/13", "patchedSince": "2025/01/14", "originSource": "CNW", "shortDescription": "Authentication bypass using an alternate path or channel vulnerability", "exploitationType": ["ransomware"], "cwes": ["CWE-288"] }, { "cveID": "CVE-2023-3519", "euvdID": "EUVD-2023-44176", "vendorProject": "Citrix", "product": "NetScaler ADC and NetScaler Gateway", "dateReported": "2025/01/23", "patchedSince": "2023/07/18", "originSource": "CNW", "shortDescription": "Unauthenticated remote code execution", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2023-27997", "euvdID": "EUVD-2023-31722", "vendorProject": "Fortinet", "product": "FortiOS and FortiProxy", "dateReported": "2025/01/23", "patchedSince": "2023/06/09", "originSource": "CNW", "shortDescription": "Heap-based buffer overflow vulnerability may allow remote attackers to execute arbitrary code or commands", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2023-46604", "euvdID": "EUVD-2023-2719", "vendorProject": "Apache", "product": "ActiveMQ", "dateReported": "2025/01/23", "patchedSince": "2023/10/27", "originSource": "CNW", "shortDescription": "RCE vulnerability that allows remote attackers with network access to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2023-22515", "euvdID": "EUVD-2023-26655", "vendorProject": "Atlassian", "product": "Confluence Server and Data Server", "dateReported": "2025/01/23", "patchedSince": "2023/10/04", "originSource": "CNW", "shortDescription": "Vulnerability in publicly accessible Confluence Data Center and Server instances that enables the creation of unauthorized Confluence administrator accounts and access to a Confluence instance", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2023-46747", "euvdID": "EUVD-2023-50916", "vendorProject": "F5", "product": "BIG-IP", "dateReported": "2025/01/23", "patchedSince": "2023/10/26", "originSource": "CNW", "shortDescription": "Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2023-48788", "euvdID": "EUVD-2023-52821", "vendorProject": "Fortinet", "product": "FortiClientEMS", "dateReported": "2025/01/23", "patchedSince": "2024/03/12", "originSource": "CNW", "shortDescription": "SQLi vulnerability in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attackers to execute unauthorized code or commands.", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2020-1472", "euvdID": "EUVD-2020-12346", "vendorProject": "Microsoft", "product": "Netlogon (ZeroLogon)", "dateReported": "2025/01/23", "patchedSince": "2020/08/11", "originSource": "CNW", "shortDescription": "Elevation of privilege vulnerability that exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC).", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2020-0787", "euvdID": "EUVD-2020-2274", "vendorProject": "Microsoft", "product": "Windows BITS26", "dateReported": "2025/01/23", "patchedSince": "2020/03/10", "originSource": "CNW", "shortDescription": "Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability.", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2017-0144", "euvdID": "EUVD-2017-0511", "vendorProject": "Microsoft", "product": "Windows (SMBv1)", "vulnerabilityName": "EternalBlue", "dateReported": "2025/01/23", "patchedSince": "2017/03/14", "originSource": "CNW", "shortDescription": "The SMBv1 server in multiple Microsoft Windows SMBv1 allows remote attackers to execute arbitrary code via crafted packets.", "exploitationType": ["ransomware"] }, { "cveID": "CVE-2024-8963", "euvdID": "EUVD-2024-49510", "vendorProject": "Ivanti", "product": "Cloud Services Appliance (CSA)", "dateReported": "2025/01/17", "patchedSince": "2024/09/10", "originSource": "CNW", "shortDescription": "Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.", "exploitationType": ["unknown"] }, { "cveID": "CVE-2024-8190", "euvdID": "EUVD-2024-49004", "vendorProject": "Ivanti", "product": "Cloud Services Appliance (CSA)", "dateReported": "2025/01/17", "patchedSince": "2024/09/10", "originSource": "CNW", "shortDescription": "OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker with admin privileges to obtain RCE.", "exploitationType": ["unknown"] }, { "cveID": "CVE-2024-9380", "euvdID": "EUVD-2024-49898", "vendorProject": "Ivanti", "product": "Cloud Services Appliance (CSA)", "dateReported": "2025/01/17", "patchedSince": "2024/10/08", "originSource": "CNW", "shortDescription": "OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.", "exploitationType": ["unknown"] } ]